CVE-2018-17243: SQL Injection
Published Sep 20, 2018
·Updated
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
Affected Software
1 affected component
ZohoCorp ManageEngine OpManager<12.3
Event History
Sep 20, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-17243?
CVE-2018-17243 is a vulnerability in Zoho ManageEngine OpManager that allows SQL Injection.
2
How severe is CVE-2018-17243?
CVE-2018-17243 has a severity rating of 9.8, which is considered critical.
3
Which version of Zoho ManageEngine OpManager is affected by CVE-2018-17243?
CVE-2018-17243 affects Zoho ManageEngine OpManager version up to but not including 12.3.
4
What is SQL Injection?
SQL Injection is a web application vulnerability that allows an attacker to manipulate database queries by injecting malicious SQL code.
5
How can I fix the CVE-2018-17243 vulnerability?
To fix the CVE-2018-17243 vulnerability, you should upgrade Zoho ManageEngine OpManager to version 12.3 or later.